The typosquatted “@acitons/artifact” package targeted GitHub’s CI/CD workflows, stealing tokens and publishing malicious ...
The bug exposes the Metro development server to remote attacks, allowing arbitrary OS command execution on developer systems ...